CVE-2026-51665: TOTOLINK T6 vulnerability
Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated attacker who can send requests to the router's web management endpoint can attempt to retrieve traceroute diagnostic logs. The issue affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.
What access or interaction is required for exploitation?
No authentication is required. An attacker needs the ability to send a crafted POST request to /cgi-bin/cstecgi.cgi targeting the getTracerouteCfg function.
How can I determine whether my device is affected?
Check whether the device is a TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. Affected devices expose the vulnerable getTracerouteCfg functionality through the specified CGI endpoint without authentication.